Security Guides
You can change a password, not a driver's license — what Times Car members should do after the breach
About 6.6 million Times Car accounts were exposed in a breach that included driver's license images. Based on the operator's official notices: what leaked, who is affected, and what members can do now to prevent identity fraud.
For: anyone who has used Times Car or Times Business Service in Japan — including people who left the service or only started an application — and anyone who runs a service that collects identity documents. This article is based on the operator's official notices and does not cover attack techniques.
What members should do today
Check whether you are affected — former members and unfinished applicants count
Affected people are Times Car members and former members (including those who applied but did not complete registration), and Times Business Service members and former members. That includes people who used the service years ago and people who uploaded a license image but never finished signing up. The company says it will contact affected people individually. If you might be affected, you do not need to wait for that notice to take the steps below.
Do not follow links or instructions in emails, texts or calls claiming to be the company
The leaked data combines name, address, date of birth, phone number and email address. With all of that, a scammer can write a very convincing message. If you get a message about "refund procedures", "re-submitting your license for verification" or "re-registering your card", do not open the link; open the official app or website yourself instead. The company also asks members not to enter passwords, verification codes or card details in response to messages that impersonate it (see What is phishing?).
Register a fraud alert (self-declaration) with Japan's three credit bureaus
This is available when your name may be misused because an identity document was lost, stolen or leaked. Once registered, lenders and card issuers see the note when they check your file and review applications more carefully. Japan has three credit bureaus — CIC, JICC and the Japanese Bankers Association's credit information center — with different member companies, so registering with all three gives the widest coverage. Applications are accepted online or by post (fees and methods differ; see the sources at the end).
Request your credit file and look for accounts you did not open
A fraud alert does not block applications; it asks lenders to be more careful. So also keep a way to confirm nothing was actually opened in your name. Each bureau lets you request your own credit file. Check it once now and again a few months later for cards or loans you never applied for. If you receive an unfamiliar contract, a collection notice or mail from a business you never used, contact that business and your local police station.
If you no longer use the service, request deletion of your data
Japan's Act on the Protection of Personal Information lets you request that a business stop using or delete your data when a reportable leak has occurred or when the business no longer needs the data (Article 35, paragraph 5). Former members, people who only started an application, and anyone who does not plan to use the service again can ask, through the contact form on the official site, for deletion of their data, including license images. Some records may have to be kept by law, but getting a written answer on what remains and when it will be deleted is worth it on its own.
Stop password reuse (changing your Times Car password is not required)
The company says passwords were stored in a form that cannot be restored and that the leaked data cannot be used to misuse accounts, so it is not asking for a change. If you use the same password on other services, though, separate them now. A password manager is the realistic way to do the inventory.
Corporate account admins: warn staff about emails impersonating partners
For corporate members, department names were also leaked. Name, department and email address together make it easier to write emails that impersonate a business partner or a colleague. Circulate a rule now: requests such as "our bank account has changed" or "please review this urgently" are verified through another channel, such as a phone call (protecting your own domain: Email spoofing and SPF, DKIM, DMARC).
What happened (from Times Mobility's notices)
Times Mobility Co., Ltd., together with its parent Park24 Co., Ltd., published a first notice on September 25, 2026 and a second on September 28. Everything below is as stated in the company's official notices.
Sep 25, 2026, 9:07
The company detected unauthorized access to its systems, began an investigation and found traces of a third party accessing the system.Sep 25
First notice published on the possibility of a personal data leak.By Sep 26, 7:25
The access route and communication with the attacker were cut off. The company confirmed access was no longer possible and continued monitoring.Sep 28
Second notice: an investigation with outside specialists confirmed that some member data had been obtained by a third party. Reported to the Personal Information Protection Commission and the police.
- Who
- Times Car members and former members (including applicants who did not complete registration), and Times Business Service members and former members. About 6.6 million accounts
- Leaked items
- Name, address, date of birth, phone number, email address, driver's license information, identity-document information (such as driver's license images), department name for corporate members, linked-service IDs
- Credit cards
- Confirmed not leaked
- Passwords
- Stored in a form that cannot be restored; the company says the data cannot be used to misuse accounts
- Secondary harm
- As of the notice, no evidence that the data was published or misused
- Cause
- Not disclosed. Forensic investigation with an outside firm is under way; recurrence-prevention measures and timelines will be published in a later notice
- Contact
- Dedicated line 0120-25-8924 (24 hours, Japan) and the contact form on the official site
How to read it: 'no misuse confirmed' does not mean 'safe'
The company says it has found no public exposure or misuse so far. That means nothing has been found yet, not that nothing will be used later. When and where the data is used is up to whoever took it. Identity-document images in particular keep their value for years. Think of your precautions in years, not weeks (the CIC and JICC fraud alerts stay registered for five years).
Why the license image is the heaviest item
License image + name, address, date of birth
↓→
Contracts or sign-ups in your name
→ Fraud alert at all three credit bureaus / check your credit file
Name + phone number + email
↓→
Convincing follow-on emails, texts and calls
→ Do not open links; check in the official app
Name + department (corporate members)
↓→
Emails impersonating partners or colleagues
→ Verify account changes outside email
Over once you change it
- Password (not restorable here; just stop reusing it)
- Credit card (not leaked here; could be reissued if it were)
- Email address and phone number (a hassle, but changeable)
Things you cannot change yourself
- Name and date of birth
- License number and face photo
- Address (unless you move)
When a password leaks, changing it makes the old one worthless. Identity-document images do not work that way. And for online contracts in Japan, a common verification method has been simply sending a photo of your license plus a selfie.
This site's view: image-only ID checks are being phased out, but not yet
In June 2025, Japan's National Police Agency promulgated a rule change that abolishes the non-face-to-face verification method based on sending images of identity documents, used for things like opening bank accounts, because forged-document images make impersonation too easy. Verification is moving to methods such as reading the document's IC chip. The change is announced to take effect in April 2027.
In other words, the idea that a license image alone can pass as proof of identity has been judged unsafe by the regulators themselves, and is on its way out. Until it takes effect, and for services outside that rule (many services ask for a license image for age checks or sign-up), an image can still work as ID. That gap is why this site recommends the fraud alert and credit-file checks.
For those who run services that collect identity documents
The leaked items included former members and applicants who never completed registration. The company has not disclosed what it stored, how, or why it kept it. A car-sharing service has business reasons of its own, such as confirming a valid license for each rental. With that said, three points are worth reviewing for any service that holds identity documents.
Separate 'the result of the check' from 'the image used for the check'
After verification, day-to-day operations usually need only when, with which document and by whom the check was done, plus the license expiry date. For each item, confirm whether keeping the image itself is required by law or audit, or whether it stays only because no one built a way to delete it.
Set a deletion deadline for images of former members and unfinished applicants
Japan's privacy law asks businesses to make efforts to delete personal data without delay once it is no longer needed (Article 22, a duty of effort), and after a leak, individuals can demand deletion (Article 35(5)). Document images of people who left or abandoned sign-up are not used by the business but are still in scope when a breach happens. Keep them for the legally required period if there is one, otherwise set a short deadline, and make them delete automatically when it passes. Manual deletion does not last.
Store images somewhere the web tier cannot read
If the web system that takes sign-ups and bookings can read the document-image store with the same permissions, breaking the web side exposes the images too. Keep images in a separate store with separate keys, and let the web side see only a "verified" result. The underlying ideas are covered in The minimum security baseline for organizations and Authentication vs. authorization.
For a comparison with other major Japanese breaches disclosed the same year, see Japan's major data breaches of 2026; for a case where the leaked data was not the images but the information around them, see the Gyazo breach.
Sources (public record)
The facts in this article come from the public sources below. Undisclosed methods or causes of the intrusion are not speculated on.
- Times Mobility Co., Ltd., notice on possible personal data leak from unauthorized access to the Times Car website (first notice, September 25, 2026, Japanese) — share.timescar.jp
- Times Mobility Co., Ltd., investigation results and next steps regarding unauthorized access to the Times Car website (second notice, September 28, 2026, Japanese) — share.timescar.jp
- Credit-bureau self-declaration (Japanese): CIC / JICC / Japanese Bankers Association credit information center
- Act on the Protection of Personal Information, Articles 22 and 35 (Japanese) — e-Gov Law Search
- National Police Agency (JAFIC), Q&A on the 2025 amendment abolishing high-impersonation-risk identity verification methods (promulgated June 24, 2025, Japanese) — npa.go.jp
Update history
2026-09-29: First version, based on Times Mobility's notices of September 25 (first) and September 28 (second). The company is continuing its forensic investigation and plans to publish the cause and prevention measures later; this article will be updated when it does.
Read next
- Follow-on scams: What is phishing? / Fake virus warnings (tech-support scams)
- Passwords: Choosing a password manager / Choosing multi-factor authentication
- Other major breaches this year: Japan's major data breaches of 2026 / The Gyazo breach
- For operators: The minimum security baseline for organizations
FAQ
QWhat was leaked in the Times Car breach?
According to the second notice from operator Times Mobility Co., Ltd. on September 28, 2026, a third party obtained the following for about 6.6 million accounts: name, address, date of birth, phone number, email address, driver's license information, identity-document information (such as driver's license images), department names for corporate members, and linked-service IDs. The company confirmed that credit card information was not leaked.
QAm I affected?
The company lists Times Car members and former members (including people who applied but never completed registration), and Times Business Service members and former members. People who left the service long ago, or who only started an application, are included. The company says it will contact affected people individually.
QShould I change my password?
The company says passwords were stored in a form that cannot be restored and that the leaked data cannot be used to misuse accounts, so it is not asking members to change them. If you use the same password on other services, though, this is a good moment to stop reusing it.
QWhy is a leaked driver's license image dangerous?
Driver's license images are accepted as identity documents for many online contracts and sign-ups. An image that shows your name, address, date of birth and face can be used by someone else to apply for services in your name. Unlike a password, you cannot change your license number, photo or date of birth. The company says it has not found any public exposure or misuse so far, but registering a fraud alert with the credit bureaus is a sensible precaution.
QWhat is a credit-bureau fraud alert in Japan?
Japan's three credit bureaus — CIC, JICC and the Japanese Bankers Association's credit information center (KSC) — let you register a self-declaration when your identity documents are lost, stolen or leaked and your name may be misused. Lenders and card issuers that check your file see the note and can review applications more carefully. Because each bureau has different member companies, registering with all three gives the widest coverage. The alert does not block applications, and at least one bureau notes it is not checked when bank deposit accounts are opened.
QWeren't they supposed to delete former members' data?
Article 22 of Japan's Act on the Protection of Personal Information says businesses must 'make efforts' to delete personal data without delay once it is no longer needed — a duty of effort, not a strict obligation. Some records must be kept by law depending on the business, and the company has not said why it kept former members' data. Under Article 35(5), however, individuals can request that data be stopped or deleted when a reportable leak has occurred or when the business no longer needs it. Former members can ask for deletion through the contact form on the official site.
QWhat caused the breach?
As of September 28, 2026, the method and cause of the unauthorized access had not been disclosed. The company is running a forensic investigation with an outside firm and says it will publish recurrence-prevention measures, with timelines, in a later notice.